PT-2019-1773 · Cisco · Cisco Small Business Spa514G Ip Phone

Published

2019-03-13

·

Updated

2019-10-09

·

CVE-2018-0389

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco Small Business SPA514G IP Phones versions 7.6.2SR2 and earlier
Description A vulnerability in the implementation of Session Initiation Protocol (SIP) processing could allow an unauthenticated, remote attacker to cause an affected device to become unresponsive, resulting in a denial of service (DoS) condition. The vulnerability is due to improper processing of SIP request messages by an affected device. An attacker could exploit this vulnerability by sending crafted SIP messages to an affected device. A successful exploit could allow the attacker to cause the affected device to become unresponsive, resulting in a DoS condition that persists until the device is restarted manually.
Recommendations For Cisco Small Business SPA514G IP Phones versions 7.6.2SR2 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the SIP protocol to minimize the risk of exploitation. Avoid using the affected SIP implementation until the issue is resolved.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01420
CVE-2018-0389

Affected Products

Cisco Small Business Spa514G Ip Phone